Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
squid vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2016-3947
Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid prior to 3.5.16 and 4.x prior to 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log ...
Squid-cache Squid 4.0.5
Squid-cache Squid 4.0.4
Squid-cache Squid 4.0.3
Squid-cache Squid 4.0.2
Squid-cache Squid 4.0.1
Squid-cache Squid 4.0.6
Squid-cache Squid 4.0.7
Squid-cache Squid
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 15.10
5
CVSSv2
CVE-2016-2570
The Edge Side Includes (ESI) parser in Squid 3.x prior to 3.5.15 and 4.x prior to 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/Cu...
Squid-cache Squid 4.0.3
Squid-cache Squid 4.0.2
Squid-cache Squid 3.4.8
Squid-cache Squid 3.4.4
Squid-cache Squid 3.4.1
Squid-cache Squid 3.4.0.3
Squid-cache Squid 3.3.5
Squid-cache Squid 3.3.4
Squid-cache Squid 3.3.0.3
Squid-cache Squid 3.3.0.2
Squid-cache Squid 3.2.4
Squid-cache Squid 3.2.3
Squid-cache Squid 3.2.0.9
Squid-cache Squid 3.2.0.8
Squid-cache Squid 3.2.0.18
Squid-cache Squid 3.2.0.17
Squid-cache Squid 3.2.0.10
Squid-cache Squid 3.2.0.1
Squid-cache Squid 3.1.4
Squid-cache Squid 3.1.3
Squid-cache Squid 3.1.1
Squid-cache Squid 3.1.0.9
5
CVSSv2
CVE-2016-2572
http.cc in Squid 4.x prior to 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.
Squid-cache Squid 4.0.1
Squid-cache Squid 4.0.3
Squid-cache Squid 4.0.2
Squid-cache Squid 4.0.6
Squid-cache Squid 4.0.5
Squid-cache Squid 4.0.4
4
CVSSv2
CVE-2014-9749
Squid 3.4.4 up to and including 3.4.11 and 3.5.0.1 up to and including 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability."
Squid-cache Squid 3.4.10
Squid-cache Squid 3.4.12
Squid-cache Squid 3.4.5
Squid-cache Squid 3.4.6
Squid-cache Squid 3.4.7
Squid-cache Squid 3.4.8
Squid-cache Squid 3.5.0.1
Squid-cache Squid 3.5.0.2
Squid-cache Squid 3.5.0.3
Squid-cache Squid 3.5.0.4
Squid-cache Squid 3.4.4
Squid-cache Squid 3.4.9
Squid-cache Squid 3.4.11
Squid-cache Squid 3.4.13
Squid-cache Squid 3.5.1
Opensuse Opensuse 13.1
Opensuse Opensuse 13.2
6.8
CVSSv2
CVE-2015-5400
Squid prior to 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote malicious users to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.
Fedoraproject Fedora 22
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Squid-cache Squid
4.3
CVSSv2
CVE-2015-0881
CRLF injection vulnerability in Squid prior to 3.1.1 allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.
Squid-cache Squid
6.4
CVSSv2
CVE-2014-7141
The pinger in Squid 3.x prior to 3.4.8 allows remote malicious users to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.
Squid-cache Squid 3.4.1
Squid-cache Squid 3.4.0.3
Squid-cache Squid 3.1.14
Squid-cache Squid 3.1.15
Squid-cache Squid 3.1.21
Squid-cache Squid 3.1.22
Squid-cache Squid 3.1.8
Squid-cache Squid 3.1.9
Squid-cache Squid 3.2.0.1
Squid-cache Squid 3.2.0.16
Squid-cache Squid 3.2.0.17
Squid-cache Squid 3.2.0.6
Squid-cache Squid 3.2.0.7
Squid-cache Squid 3.2.3
Squid-cache Squid 3.2.4
Squid-cache Squid 3.3.0.1
Squid-cache Squid 3.3.0.2
Squid-cache Squid 3.3.3
Squid-cache Squid 3.3.4
Squid-cache Squid 3.4.7
Squid-cache Squid 3.4.6
Squid-cache Squid 3.4.0.2
6.4
CVSSv2
CVE-2014-7142
The pinger in Squid 3.x prior to 3.4.8 allows remote malicious users to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.
Oracle Solaris 11.2
Canonical Ubuntu Linux 14.10
Canonical Ubuntu Linux 14.04
Squid-cache Squid 3.4.5
Squid-cache Squid 3.4.4
Squid-cache Squid 3.1.1
Squid-cache Squid 3.1.10
Squid-cache Squid 3.1.17
Squid-cache Squid 3.1.18
Squid-cache Squid 3.1.19
Squid-cache Squid 3.1.5
Squid-cache Squid 3.1.5.1
Squid-cache Squid 3.2.0.11
Squid-cache Squid 3.2.0.12
Squid-cache Squid 3.2.0.2
Squid-cache Squid 3.2.0.3
Squid-cache Squid 3.2.1
Squid-cache Squid 3.2.10
Squid-cache Squid 3.2.6
Squid-cache Squid 3.2.7
Squid-cache Squid 3.3.10
Squid-cache Squid 3.3.11
6.8
CVSSv2
CVE-2014-6270
Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based ...
Squid-cache Squid 2.7.stable2
Squid-cache Squid 2.7.stable3
Squid-cache Squid 2.7.stable1
Squid-cache Squid 2.7.stable8
Squid-cache Squid 2.7.stable9
Squid-cache Squid 2.6.stable8
Squid-cache Squid 2.6.stable9
Squid-cache Squid 2.6.stable16
Squid-cache Squid 2.6.stable17
Squid-cache Squid 2.5.stable1
Squid-cache Squid 2.5.stable2
Squid-cache Squid 2.5.stable10
Squid-cache Squid 2.5.stable11
Squid-cache Squid 2.4.stable4
Squid-cache Squid 2.4.stable5
Squid-cache Squid 3.0
Squid-cache Squid 3.0.stable12
Squid-cache Squid 3.0.stable13
Squid-cache Squid 3.0.stable19
Squid-cache Squid 3.0.stable2
Squid-cache Squid 3.0.stable3
Squid-cache Squid 3.0.stable4
5
CVSSv2
CVE-2014-0128
Squid 3.1 prior to 3.3.12 and 3.4 prior to 3.4.4, when SSL-Bump is enabled, allows remote malicious users to cause a denial of service (assertion failure) via a crafted range request, related to state management.
Squid-cache Squid 3.1
Squid-cache Squid 3.1.0.15
Squid-cache Squid 3.1.0.16
Squid-cache Squid 3.1.0.17
Squid-cache Squid 3.1.0.7
Squid-cache Squid 3.1.0.8
Squid-cache Squid 3.1.14
Squid-cache Squid 3.1.15
Squid-cache Squid 3.1.8
Squid-cache Squid 3.1.9
Squid-cache Squid 3.2.0.15
Squid-cache Squid 3.2.0.16
Squid-cache Squid 3.2.0.5
Squid-cache Squid 3.2.0.6
Squid-cache Squid 3.2.2
Squid-cache Squid 3.2.3
Squid-cache Squid 3.1.0.1
Squid-cache Squid 3.1.0.10
Squid-cache Squid 3.1.0.18
Squid-cache Squid 3.1.0.2
Squid-cache Squid 3.1.0.9
Squid-cache Squid 3.1.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
IMAP
CVE-2024-4367
server-side request forgery
information disclosure
CVE-2024-34342
CVE-2024-4281
CVE-2024-3507
CVE-2024-25560
CVE-2024-34574
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »